Facebook Graph API
The Facebook Graph API v26.0 (released July 2026) is the primary way to read and write data to Facebook — Pages, Posts, Events, Groups, Insights, Ads, and more.
API Overview
v26.0 · July 2026The Facebook Graph API v26.0 is the standard way to read from and write to the Facebook social graph. Developers can build apps that manage Facebook Pages, publish and schedule posts, read Page insights, moderate comments, manage ads, and more. Authentication uses OAuth 2.0 with Page Access Tokens for most Page-level operations.
v26.0 Breaking Changes: The Commerce Order Management API (47 endpoints) has been fully deprecated and removed. Legacy "New Pages Experience" fields and several legacy protocol features have been phased out. Check the official changelog before updating your integration.
API Features
| Feature | Description | Required Permission | Status |
|---|---|---|---|
| Post Publishing | Publish text, photo, video, and link posts to a Facebook Page | pages_manage_posts | Available |
| Post Scheduling | Schedule posts for future publication on a Facebook Page | pages_manage_posts | Available |
| Page Insights | Access engagement, reach, impressions, and demographic data | pages_read_engagement | Available |
| Comment Moderation | Read, reply, hide, and delete comments on Page posts | pages_manage_engagement | Available |
| Messenger Platform | Send and receive messages via Facebook Messenger | pages_messaging | Available |
| Events Management | Create, update, and delete Facebook Events for a Page | pages_manage_metadata | Available |
| Marketing / Ads API | Full programmatic control of ad campaigns, sets, and creatives | ads_management | Advanced |
| Business Management | Access business assets, portfolios, and system users | business_management | Advanced |
| Webhooks | Subscribe to Page events, messages, and mentions in real time | Subscription setup required | Available |
Rate Limits
Graph API v26.0| Limit Type | Limit | Scope | Notes |
|---|---|---|---|
| Platform Rate Limit | 200 calls / user / hour | Per app-user pair | Standard limit for most Graph API endpoints |
| Business Use Case (BUC) | Dynamic — based on engagement | Per app / Page | Applies to Marketing API and high-volume Page operations |
| App-Level Token | 200 × number of users | Per hour per app | Scales with active user base |
Monitor rate limit consumption using the x-app-usage and x-business-use-case-usage HTTP response headers. When limits are exceeded, the API returns API_EC_TOO_MANY_CALLS. Implement exponential backoff.
Media Requirements
| Media Type | Supported Formats | Max Size | Notes |
|---|---|---|---|
| Photos | JPG, PNG, GIF, TIFF, BMP, WebP, HEIF | 10 MB | JPG recommended; animated GIFs supported |
| Videos | MP4, MOV, AVI, 3GPP, WMV, FLV | 10 GB | MP4 H.264 with AAC audio strongly recommended |
| Video Max Duration | Up to 240 minutes | — | For Reels, max 90 seconds |
| Video Resolution | 720p minimum recommended | — | 1080p for best quality |
| Video Frame Rate | Up to 60 fps | — | 30 fps recommended for standard posts |
| Aspect Ratios | 16:9 (landscape), 9:16 (vertical), 1:1 (square) | — | 1:1 recommended for feed posts |
Authentication & Access
| Requirement | Details |
|---|---|
| Auth Method | OAuth 2.0 via Facebook Login for Business |
| Token Type | Page Access Token (for Page operations), User Access Token, App Access Token |
| Developer Account | Meta Developer account at developers.facebook.com |
| App Review | Required for production-level permissions (almost all write operations) |
| Business Verification | Required for advanced permissions such as ads_management and business_management |
| 2FA Requirement | Accounts linked to apps performing sensitive actions must have 2FA enabled |
Common Permission Scopes
Quick Start Guide
Create a Meta App
Register a new app at developers.facebook.com. Add Facebook Login and Pages API products to your app.
Generate a Page Access Token
GET https://graph.facebook.com/v26.0/me/accounts ?access_token=USER_ACCESS_TOKEN
From the response, use the access_token for the target Page.
Publish a Post to a Page
POST https://graph.facebook.com/v26.0/{page-id}/feed
?message=Hello%20from%20the%20Graph%20API%21
&access_token=PAGE_ACCESS_TOKENRead Page Insights
GET https://graph.facebook.com/v26.0/{page-id}/insights
?metric=page_impressions,page_engaged_users
&period=day
&access_token=PAGE_ACCESS_TOKENCommon Errors & Solutions
| Error Code | Meaning | Common Cause | Solution |
|---|---|---|---|
| 190 | Invalid OAuth 2.0 Access Token | Expired or revoked access token | Refresh or re-generate the token; check token expiry with the Debug Token tool |
| 4 / API_EC_TOO_MANY_CALLS | Application request limit reached | Platform rate limit exceeded | Implement exponential backoff; check x-app-usage header |
| 10 / 200 | Permission denied | Missing required scope or not approved in App Review | Request the required permission via App Review and ensure user has granted it |
| 100 | Invalid parameter | Wrong field name or value format | Check the Graph API Explorer and verify field names against official docs |
| 368 | Blocked temporary | Account or app flagged for policy violations | Review the Facebook Developer Policies and contact Meta support |
Best Practices
Monitor Usage Headers
Always read x-app-usage and x-business-use-case-usage response headers to track real-time rate limit consumption.
Track the Changelog
Meta frequently releases out-of-cycle API changes. Subscribe to the official changelog to avoid surprise deprecations.
Secure Access Tokens
Never hardcode access tokens in client-side code. Store them server-side using an encrypted secrets manager. Use long-lived Page tokens where possible.
Use Webhooks Over Polling
Subscribe to Webhooks for real-time Page events and messages instead of polling the API repeatedly, which wastes rate limit budget.
Test in Explorer First
Use the Graph API Explorer to test all queries before coding them into your production app.
Exponential Backoff
When receiving rate-limit errors, wait with exponential backoff (1s, 2s, 4s, 8s...) before retrying to avoid compounding throttle penalties.